Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/varienos/agentic-workflow/workflow-update.skeletongit clone --depth 1 https://github.com/varienos/agentic-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01288 |
| Opus 5 | $0.00000 | $0.00644 |
| Sonnet 5 | $0.00000 | $0.00258 |
| Haiku 4.5 | $0.00000 | $0.00129 |
Grade A, and why
workflow-update.skeleton scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 129 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Workflow Update — Incremental Drift Guncelleme
Mevcut workflow konfigurasyonunu Codebase'in guncel durumuyla karsilastirir. Sadece degisen parcalari gunceller — tam re-bootstrap YAPMAZ. Kullanim:
/workflow-update
ADIM 1 — Mevcut Manifest'i Oku
Docbase/agentic/project-manifest.yaml dosyasini oku.
meta.last_analyzed ve meta.codebase_hash alanlarini not al.
Manifest yoksa: "Manifest bulunamadi. Once /bootstrap calistirin." uyarisi ver.
ADIM 2 — Codebase'i Yeniden Tara
Codebase dizinini tara ve su bilgileri topla:
- Mevcut dependency'ler (package.json, composer.json, pyproject.toml vb.)
- Aktif framework/ORM/deploy araclari
- Subproject dizinleri ve test komutlari
- Root config dosyalari hash'i
Bu adim yazma YAPMAZ — sadece okuma ve analiz.
ADIM 3 — Drift Raporu
Mevcut manifest ile yeni analiz arasindaki farklari raporla:
## Workflow Drift Raporu
### Yeni Tespit Edilen (+)
- +deploy/docker (Dockerfile eklenmis)
- +mobile/react-native (react-native dependency eklenmis)
### Kaldirilan (-)
- -orm/prisma (prisma dependency cikarilmis)
### Degisen (~)
- ~api subproject: test komutu jest → vitest
### Degismeyen
- orm/eloquent, backend/nodejs/express (ayni)
Uygulamak istiyor musunuz? (evet / hayir / secmeli)
ADIM 4 — Kullanici Onayi
Kullanicinin yaniti:
- evet: Tum degisiklikleri uygula
- hayir: Hicbir sey yapma, raporu kapat
- secmeli: Her degisiklik icin tek tek onayla/reddet
ADIM 5 — Incremental Guncelleme
Onaylanan degisiklikler icin:
- Manifest yedekle:
project-manifest.yaml.backupolarak kopyala - Manifest guncelle: Eklenen modulleri
modules.active'e ekle, kaldirilanlari cikar, subproject degisikliklerini yansit - Sadece degisen modullerin dosyalarini uret:
node generate.jsile--modules <degisen-moduller>parametresi - Degismeyen dosyalara DOKUNMA
.claude/custom/dizinini KORU — kullanici ozellestirmelerini silme
ADIM 6 — Meta Guncelle
Manifest meta bolumunu guncelle:
meta:
last_analyzed: <simdi>
codebase_hash: <yeni-hash>
update_history:
- date: <bugun>
action: update
changes: ["+deploy/docker", "-orm/prisma", "~api.test_command"]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 129 lines · 0 tokens per session scan A 9e2bec2401a9
workflow-update.skeleton is a command published in the GitHub repository varienos/agentic-workflow (58 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,288 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
design-to-code
Mockup-to-component pipeline using Google Stitch, 21st.dev, and Storybook MCP. Accepts a screenshot, a description, or a URL and produces production-ready React components, checking existing Storybook components before generating anything new. Use when implementing UI from a mockup or screenshot. To call the MCP tool…
memory
Search, store, and manage AI Team Memory — agent expertise, decisions, learnings, and code patterns. File-based by default, with an optional memory MCP overlay.
triage-issues
Launch the Issue Triage Agent (Haiku) to categorize and prioritize GitHub issues.
do-it-retrospective
开关本项目的本地行为反馈记录,或输出已记录问题的去敏复盘报告。参数为 on / off / status / report。.
fix-issue
!gh issue view $ARGUMENTS 2>/dev/null || echo "Could not fetch issue $ARGUMENTS".
verify
Verify factual claims in content using deep research methodology - fact-checks key assertions and updates NCI scores.